KQL: One Successful login followed by X failed login in Y time period for same user

%3CLINGO-SUB%20id%3D%22lingo-sub-2713629%22%20slang%3D%22en-US%22%3EKQL%3A%20One%20Successful%20login%20followed%20by%20X%20failed%20login%20in%20Y%20time%20period%20for%20same%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2713629%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20new%20to%20KQL%2C%20and%20struggling%20to%20find%20the%20best%20option%20to%20build%20the%20query%20for%20One%20successful%20login%20followed%20by%20X%20failed%20logins%20in%20Y%20time%20period%20for%20same%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20scenario%20is%20user%20tried%20to%20do%20password%20guess%20for%20Y%20times%20and%20succeeded%20and%20a%20successful%20login%20was%20triggered%20and%20the%20whole%20scenario%20is%20time%20boxed.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20suggestion%20will%20be%20appreciated.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20find%20almost%20similar%20query%20%22%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fquestions%2F54041200%2Fazure-log-analytics-monitoring-successful-sign-ins-following-repeated-sign-in-f%26quot%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fstackoverflow.com%2Fquestions%2F54041200%2Fazure-log-analytics-monitoring-successful-sign-ins-following-repeated-sign-in-f%22%3C%2FA%3E%26nbsp%3Bbut%20this%20does%20not%20check%20if%20successful%20login%20came%20after%20failed.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Visitor

Hello, 

 

I am new to KQL, and struggling to find the best option to build the query for One successful login followed by X failed logins in Y time period for same user.

 

The scenario is user tried to do password guess for Y times and succeeded and a successful login was triggered and the whole scenario is time boxed. 

 

Any suggestion will be appreciated. 

 

I did find almost similar query "https://stackoverflow.com/questions/54041200/azure-log-analytics-monitoring-successful-sign-ins-foll... but this does not check if successful login came after failed. 

 

Thanks in advance. 

0 Replies